Law / United States / North Carolina

North Carolina

United States law applies in North Carolina North Carolina is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of North Carolina, described on this page below, applies here too.

7 of 12 named instruments researched to a stage, across five of the six areas of law we track: 5 in force, 1 enacted but not yet in force and 1 proposed. As of 15 September 2026.

When they take effect5 of 7 carry a date, 2 do not. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 2 instruments (2 in force) 2025: 1 instrument (1 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 1
  3. Scraping law 1
  4. Cybersecurity law 1
  5. Age gating law 3
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (169 words)

North Carolina has not enacted a general-purpose AI-transparency, output-labeling, or risk-management statute; the state's only enacted AI-specific instrument criminalizes conduct rather than requiring disclosure.

Session Law 2024-37 (House Bill 591) amended North Carolina's disclosure-of-private-images and sexual-exploitation-of-a-minor statutes so that a realistic image created, adapted, or modified using artificial intelligence is treated the same as a real photograph, reaching AI-generated nonconsensual intimate images and AI-generated child sexual abuse material as criminal offenses binding any person.

Governor Stein's Executive Order No. 24 (September 2, 2025) establishes a state AI Leadership Council and an AI Accelerator and directs state agencies on their own use of artificial intelligence, but by its own terms imposes no obligations on private entities, so it is recorded here as context rather than as an instrument.

Four AI-specific bills remained in committee as of the date shown, none having passed either chamber: House Bill 1161 (omnibus AI protections), House Bill 375 (AI and synthetic media disclosure), and companion Senate Bills 624 and 963 (AI chatbot licensing and safety).

AI prohibited practices

AI-Generated Intimate Images and Child Sexual Abuse Material (Session Law 2024-37, HB 591)

N.C. Sess. Law 2024-37 (H.B. 591); N.C. Gen. Stat. §§ 14-190.5A, 14-190.13official text, North Carolina General Assembly (ncleg.gov), General Statutes by section, and Session Law 2024-37

In force since 1 December 2024. Binds public and private bodies.

What this law does

Session Law 2024-37 (House Bill 591), effective December 1, 2024, amended section 14-190.5A, disclosure of private images, and section 14-190.13, the shared definitions section for North Carolina's sexual-exploitation-of-a-minor offenses, so that 'image' and 'material' each include a realistic visual depiction created, adapted, or modified by technological means, including algorithms or artificial intelligence, such that a reasonable person would believe it depicts an identifiable person.

Under section 14-190.5A as amended, a person who knowingly discloses such a depiction of an identifiable adult without consent, with intent to coerce, harass, intimidate, demean, humiliate, or cause financial loss, commits disclosure of private images, a Class H felony for an adult offender, and the depicted person may also bring a civil action for liquidated damages of at least the higher of one thousand dollars per day of violation or ten thousand dollars, plus punitive damages and attorneys' fees.

Section 14-190.13's amended definition of material extends North Carolina's existing first, second, and third degree sexual exploitation of a minor offenses to reach AI-generated child sexual abuse material on the same terms as a photograph, without itself restating those offenses' own penalties.

What it requires

Privacy law1 instrument, 1 enacted but not yet in force

Research summary (185 words)

North Carolina has no comprehensive consumer personal-data-protection statute. The marquee candidate, House Bill 462 (the NC Personal Data Privacy Act), remains in House committee with no floor vote in either chamber. North Carolina's operative privacy statute is the Identity Theft Protection Act's breach notification duty, N.C. Gen. Stat. Secs. 75-61 and 75-65 (Chapter 75, Article 2A), which sets no numeric notification deadline, requiring only notice without unreasonable delay.

The Act's personal information definition incorporates identifying information by cross-reference to North Carolina's criminal identity-theft statute, G.S. Sec. 14-113.20(b), which lists biometric data as one of fourteen enumerated items, but no North Carolina statute anywhere defines what the term means; it is used but never defined, so whether it excludes or reaches an identifier derived from a recording cannot be determined either way.

A 2025 amendment, Session Law 2025-25, confirmed that a breach-notice violation is a violation of North Carolina's general Unfair and Deceptive Trade Practices Act, arming an individual injured by the violation with a private civil action for treble damages under G.S. Sec. 75-16, though the injury requirement is written into the deeming clause itself.

Breach notification

Identity Theft Protection Act, security breach notification

N.C. Gen. Stat. Secs. 75-61, 75-65official North Carolina statute text, General Statutes Chapter 75, Article 2A

Commencement not set. Binds private bodies.

What this law does

Any business that owns or licenses personal information of a North Carolina resident, or that conducts business in North Carolina and owns or licenses such information in any form, must give notice of a security breach to the affected person without unreasonable delay, consistent with the legitimate needs of law enforcement; the statute sets no numeric notification deadline.

Business is defined narrowly as a sole proprietorship, partnership, corporation, association, or other group, whether or not organized for profit, with no government entity included.

Personal information is a name combined with identifying information as cross-referenced from North Carolina's criminal identity-theft statute, G.S. Sec. 14-113.20(b), which lists biometric data as one of fourteen enumerated items alongside a Social Security number, a driver's license number, and financial account numbers, but no North Carolina statute anywhere defines what biometric data means for this purpose; the term is used but never defined.

Personal information excludes information a person voluntarily consented to have publicly disseminated and information made lawfully available to the general public from government records, but because biometric data is an undefined cross-referenced term, whether this carve-out would reach an identifier derived from a public recording cannot be evaluated.

A business must also notify the Consumer Protection Division of the Attorney General's Office on every breach requiring notice to any affected person, and separately, on any breach affecting more than 1,000 persons at one time, must notify nationwide consumer reporting agencies.

A violation of the notice duty is a violation of North Carolina's general Unfair and Deceptive Trade Practices Act, G.S. Sec. 75-1.1, but an individual may not sue for that violation unless injured by it; once that injury threshold is met, G.S. Sec. 75-16 arms the injured person with a civil action for treble damages. Most recently amended by Session Law 2025-25.

What it requires

Scraping law1 instrument, 1 in force

Research summary (85 words)

North Carolina's divergence from the federal baseline runs through its computer-related crime statute, Article 60 of Chapter 14, which defines authorization by reference to the computer owner's actual consent and separately criminalizes making an unauthorized copy of computer data as computer trespass, backed by a private civil action for damages including lost profits. Copyright, text-and-data-mining, and database rights are federal only; North Carolina adds nothing there.

Terms-of-service enforceability rests on ordinary North Carolina contract law, and robots.txt carries no independent legal weight in North Carolina.

Computer misuse

North Carolina Computer-Related Crime Act (unauthorized access and computer trespass)

N.C. Gen. Stat. §§ 14-453 to 14-458; § 1-539.2Aofficial text, North Carolina General Assembly (ncleg.gov), General Statutes by section

In force since 1 December 1999. Binds public and private bodies.

What this law does

North Carolina's computer-related crime statute, Article 60 of Chapter 14, defines authorization by reference to the computer owner's consent, not exceeding the scope of that consent, a standard closer to the federal Computer Fraud and Abuse Act's without-authorization and exceeds-authorized-access tests than to Virginia's narrower malicious-intent-or-deception requirement.

Computer trespass under section 14-458 makes it unlawful to use a computer or computer network without authority and with intent to make an unauthorized copy of computer data, programs, or software residing in, communicated by, or produced by a computer or network, reaching unauthorized automated copying of data from a website. A violation is a Class 3 misdemeanor, rising to a Class 1 misdemeanor or a Class I felony depending on the dollar value of resulting property damage.

A separate offense, section 14-454, criminalizes accessing a computer without authorization to defraud or to obtain property or services by false pretenses, as a Class 1 misdemeanor or a Class G felony depending on the value obtained. Accessing a government computer without authorization for any other purpose is a Class H felony under section 14-454.1, rising above the analogous private-computer offense's misdemeanor default.

Anyone injured by a violation of the computer trespass statute may bring a private civil action for damages, including lost profits, under section 1-539.2A.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (612 words)

North Carolina's product-security and cyber-resilience posture, for a private-sector operator, rests on one enacted state statute with a narrow scope: the Identity Theft Protection Act's destruction-of-records duty, N.C. Gen. Stat. section 75-64 (Chapter 75, Article 2A, added by S.L. 2005-414, s. 1, effective December 1, 2005), which requires any business that conducts business in North Carolina, or that maintains or otherwise possesses the personal information of a North Carolina resident, to take reasonable measures, described in the statute as burning, pulverizing, or shredding paper records and destroying or erasing electronic and other nonpaper media, to protect against unauthorized access to or use of personal information in connection with or after its disposal.

The duty reaches only the disposal phase; it does not extend, the way New York's SHIELD Act safeguards duty or Massachusetts's 201 CMR 17.00 do, to a general written information-security-program requirement for personal information while it remains in active use, and no such general requirement was located in North Carolina law. No enacted North Carolina statute was located that sets security requirements a connected device or software product must meet before or after it reaches the market.

North Carolina has no general private-sector duty to report an exploited vulnerability or a security incident to an authority: the state's Ransomware Act, N.C. Gen. Stat. section 143-800 (Chapter 143, Article 84, added by S.L. 2021-180, s. 38.13(a)), bars a state agency or local government entity from paying or communicating with a ransomware attacker and requires either to consult the Department of Information Technology on a ransom request, but both bound terms are defined to reach only government bodies, so this belongs with the jurisdiction's government-accountability material rather than as a row in this profile's private-sector scope.

The state's one sector-specific security regime, N.C. Gen. Stat. sections 58-39-130 to 58-39-165 (Chapter 58, Article 39, Part 3, "Customer Information Safeguards," added by S.L. 2003-262, s. 4, effective April 1, 2005), implements the federal Gramm-Leach-Bliley Act's safeguards requirements for the insurance sector, requiring each "licensee," an insurance producer, insurer, multiple employer welfare arrangement, HMO, or Chapter 58 service corporation, to implement a comprehensive written information security program with administrative, technical, and physical safeguards appropriate to its size and complexity and the nature and scope of its activities.

North Carolina has not separately adopted the newer NAIC Insurance Data Security Model Law: a full-text search of Chapter 58's own section index for "cybersecurity" and "data security" returned nothing outside this 2003 Gramm-Leach-Bliley Act (GLBA)-based Part. Because "licensee" is a role the LexLint activity vocabulary cannot yet express, no instrument for this duty is filed here (#6740), and it is recorded in this summary so a reader knows it exists.

G.S. 75-64 is enforced as a deemed violation of the state's general unfair-or-deceptive-trade-practices statute, G.S. 75-1.1: a person injured by a violation may bring a civil action under G.S. 75-16 for treble the damages found, with treble damages for a nonmanagerial employee's own acts or omissions available only where the business was negligent in training, supervising, or monitoring that employee, and the Attorney General may separately sue to enjoin a violation.

No capped or per-violation civil-penalty figure is recorded for this instrument because the statutory remedy is trebled actual damages rather than a stated amount, and no published enforcement record specific to this duty was located.

North Carolina's breach-notification duty, the Identity Theft Protection Act's G.S. 75-65, is already this jurisdiction's privacy row rather than repeated here, and a narrower, adjacent duty at G.S. 75-62(c), requiring a business handling social security numbers to make reasonable efforts, including systems testing, to ensure that Article's SSN-protection requirements are implemented, also stays with that privacy row rather than being filed separately here.

Security baseline statutes

Identity Theft Protection Act, destruction of personal information records

N.C. Gen. Stat. section 75-64 (Chapter 75, Article 2A, added by S.L. 2005-414, s. 1)Official statute text, North Carolina General Statutes, Chapter 75, Article 2A (Identity Theft Protection Act)

In force since 1 December 2005. Binds private bodies.

What this law does

Any business that conducts business in North Carolina, or that maintains or otherwise possesses the personal information of a North Carolina resident, must take reasonable measures to protect against unauthorized access to or use of that information in connection with or after its disposal.

Required measures include burning, pulverizing, or shredding paper records so the information cannot practicably be read or reconstructed, and destroying or erasing electronic and other nonpaper media the same way. "Business" excludes any government or governmental subdivision or agency.

The duty also does not apply to a bank or financial institution already complying with the Gramm-Leach-Bliley Act, a Health Insurance Portability and Accountability Act (HIPAA)-compliant health insurer or health care facility, or a consumer reporting agency already complying with the Fair Credit Reporting Act. A violation is a deemed violation of G.S. 75-1.1, enforceable by a person injured under G.S. 75-16 for treble damages or by the Attorney General to enjoin the violation.

What it requires

Age gating law3 instruments, 2 in force, 1 proposed

Research summary (113 words)

North Carolina has two in-effect adult content laws. The PAVE Act, enacted in 2023, requires websites with substantial harmful-to-minors content to age-verify visitors and is enforced only through private civil suits. House Bill 805, enacted over the Governor's veto in July 2025, requires pornography platforms to verify the age and written consent of every individual depicted and honor removal requests, effective December 1, 2025.

A separate social media minor-access bill, House Bill 301, passed the House in 2025 and the Senate in 2026 in different forms and went to a House-Senate conference committee in late June 2026. No app store or design code law has been enacted or advanced past a single chamber.

Adult content age verification (AV)

HB 8, Pornography Age Verification Enforcement (PAVE) Act

N.C. Gen. Stat. ch. 66, art. 51, sections 66-500 to 66-501 (Session Law 2023-132)official session law text

In force since 1 January 2024. Binds private bodies.

What this law does

Commercial entities that knowingly publish or distribute material harmful to minors from a website where more than one third of the content meets that definition must verify that visitors are 18 or older using a commercial database or another commercially reasonable method. Providers may not retain identifying information after access is granted, and enforcement is solely through private civil suits by parents, guardians, or affected individuals.

Note and primary source

HB 805, Prevent Sexual Exploitation of Women and Minors Act

N.C. Gen. Stat. ch. 66, art. 51A, sections 66-505 to 66-510 (Session Law 2025-84)official session law text

In force 10 months, effective 1 December 2025. Binds private bodies.

What this law does

Operators of websites and apps that publish pornographic images must verify, before publication, that every individual depicted was at least 18 when the image was created and gave explicit written consent to each act and to distribution, backed by a signed consent form and matching government-issued identification.

Operators must display removal instructions, remove images within 72 hours of a request from a depicted individual or law enforcement, and block removed images from re-publication; this regulates verification of people appearing in content rather than website visitors. The act was enacted over the Governor's veto on July 29, 2025.

Note and primary source

Social media and minors

HB 301, social media and minors safety act

H.B. 301, 2025-2026 Session (General Assembly, as passed by both chambers in differing forms)official bill status and text

Proposed: draft date not recorded. In reconciliation between two chambers, dated 24 June 2026, as of 12 September 2026. Binds private bodies.

What this law does

As passed by the House 106-6 in May 2025, the bill would bar children under 14 from holding social media accounts and require parental consent for 14 and 15 year olds, with age verification duties on platforms. The Senate passed a revised committee substitute 48-0 on June 10, 2026, the House voted not to concur on June 23, 2026, and a conference committee was appointed the next day to reconcile the versions.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.